minimist vulnerabilities
CVEs whose affected-version data names the minimist package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2021-44906Critical· 9.8PoCMinimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
▾ Abyssalsubstack · minimistEPSS 4.6%via NVD
CVE-2020-7598Medium· 5.6PoCminimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
▾ Twilightsubstack · minimistEPSS 1.9%via NVD